Skip to content
Analyzing public Domain Exposure telemetry

Analyzing public Domain Exposure telemetry

lunarcyber.com September 18, 2026

A company does not have to suffer a publicly disclosed breach for its credentials to end up in the hands of attackers.

Infostealer malware, breach databases and credential dumps continuously expose employee passwords, browser sessions and other access data outside the corporate perimeter.

To see what this looks like in practice, Lunar Cyber analyzed public Domain Exposure reports for ten large organizations across technology, financial services, retail, media, energy and manufacturing.

Across the ten domains, Lunar identified 747,485 credential exposure events tied to accounts using the organizations’ own email domains .

Every company in the sample also appeared in infostealer data.

The figures represent exposure events, not unique people or accounts . The same identity can appear in multiple sources or events.

The distinction between employee and client exposure is also important.

An employee-domain event means the exposed account uses the organization’s own email domain.

A client/service event means the organization’s domain appears as the login or service destination, but the exposed account belongs to a different email domain.

Without making that distinction, raw exposure numbers can be misleading.

Consumer exposure can dwarf employee exposure

Apple is the clearest example.

Lunar observed more than 46 million exposure events associated with Apple , but only 209,767 were tied to accounts using @apple.com addresses .

The remaining 45.9 million were primarily credentials belonging to users accessing Apple services.

OpenAI showed an even larger difference.

Its report contained more than 11.1 million total exposure events , but only 531 were tied to @openai.com accounts .

That does not make the broader exposure irrelevant. Customer credentials can still be valuable to attackers.

But it is a different problem from an employee credential that may provide access to corporate infrastructure.

Some companies show the opposite pattern

For other organizations, employee exposure made up a much larger of the data.

At Owens Corning, 52,003 of 55,561 observed events — 93.6% — were tied to accounts using the company’s own domain .

At Eversource, 44,349 of 83,098 events — 53.4% — were employee-domain exposures .

At Mastercard, 37,629 of 145,765 events — 25.8% — involved Mastercard-domain accounts .

That distinction matters because an exposed corporate identity can potentially provide access to email, VPNs, SaaS applications, developer infrastructure, internal systems and cloud environments.

Infostealers appeared across all ten organizations

Traditional breach datasets accounted for much of the exposure, but infostealer malware was present across every company in the sample.

In total, Lunar identified 10,760,892 infostealer-derived events , representing approximately 17% of all exposure events in the sample .

The differed sharply by organization:

Interactive Brokers: 13.4%

Common malware families appearing across Lunar’s reports included LummaC2, Rhadamanthys, RedLine, Vidar and Acreed .

This is different from finding an email address inside an old breach database.

Infostealer malware operates directly on infected devices. Depending on the malware and infection, it can collect passwords, browser cookies, authenticated sessions and machine credentials.

That can give attackers something much more useful than a password they still need to validate.

The exposed services show why this matters

The research also identified credentials associated with enterprise access services.

Across the sample, Lunar observed services including:

Microsoft, Okta, Citrix, Git, Jira, Salesforce, OneLogin, Cisco AnyConnect, Fortinet VPN, F5 and Pulse Secure.

Broadcom’s exposure data, for example, included credentials associated with Okta, Jira, Microsoft, OneLogin, Salesforce and Git .

Apple’s data included Citrix, Git, Cisco AnyConnect, Fortinet VPN and Microsoft .

Disney’s included Microsoft, Citrix, F5, Okta, Git, Pulse Secure and Jira .

The presence of these services does not mean the service provider or the organization itself was breached.

It means credentials associated with access to those services appeared in the exposure telemetry.

That is the risk security teams need to investigate.

A password is no longer the only credential worth stealing

Passwords are only one part of modern authentication.

Infostealers increasingly collect artifacts that can be immediately useful to attackers:

Browser session cookies

Authentication tokens

Personal access tokens

Service-account credentials

A password may be stopped by MFA.

A stolen authenticated session may allow an attacker to bypass the login process entirely.

A stolen machine credential can provide direct access to cloud environments, source-code repositories, AI platforms or production systems without involving a human account at all.

This is why monitoring only leaked usernames and passwords is becoming insufficient.

Exposure does not mean the company was breached

The numbers in this research should not be interpreted as confirmed compromises of the organizations themselves.

Finding an employee credential in an infostealer log or breach dataset means that credential has been exposed outside the organization’s control.

It does not prove that an attacker successfully used it.

Likewise, a customer credential associated with a company’s service does not mean the company’s systems were compromised.

The data should therefore be treated as external access-risk intelligence , not a list of confirmed breaches.

The purpose of monitoring this data is to give security teams a chance to investigate and revoke compromised access before it is used.

The risk often exists outside the perimeter

Most corporate security controls look inward.

They monitor endpoints, networks, identity providers, repositories, cloud infrastructure and employee activity.

But once credentials leave those systems, the organization may have little visibility into where they go .

An employee laptop can become infected outside the office.

A browser session can be stolen.

An API key can be collected from a developer endpoint.

A credential can appear in an infostealer log and later be redistributed through breach collections or underground markets.

None of those events necessarily generates an internal security alert.

External exposure monitoring is designed to find that missing piece.

Check your own domain

The ten-company sample shows how different exposure profiles can be.

At Apple, employee accounts represented less than 1% of the overall exposure associated with the domain.

At Owens Corning, they represented more than 93%.

At Disney and Broadcom, infostealer data accounted for roughly one-third of all observed exposure.

There is no single exposure pattern that applies to every company.

Lunar Cyber’s Domain Exposure tool lets organizations check their own domain and see:

Other indicators observed during the 12 months

Check your domain:

Lunar Cyber analyzed publicly accessible Domain Exposure reports for ten large organizations: Apple, Mastercard, Disney, OpenAI, Interactive Brokers, Chewy, Owens Corning, Eversource, Broadcom and Target.

The reports cover rolling 12-month periods and combine data from infostealer logs and breach-related sources.

An employee exposure event is an event where the exposed account identifier uses the queried organization’s email domain.

A client exposure event is an event where the organization’s domain appears as the login or service destination while the exposed account uses another email domain.

The figures represent exposure events, not unique people, unique credentials or confirmed compromises. The same account can appear in multiple exposure events.

The ten-company sample was selected to illustrate different exposure patterns and should not be treated as statistically representative of all public companies.